CVE-2009-2719

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
10/08/2009
Last modified:
09/04/2025

Description

The Java Web Start implementation in Sun Java SE 6 before Update 15 allows context-dependent attackers to cause a denial of service (NullPointerException) via a crafted .jnlp file, as demonstrated by the jnlp_file/appletDesc/index.html#misc test in the Technology Compatibility Kit (TCK) for the Java Network Launching Protocol (JNLP).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sun:java_se:*:14:*:*:*:*:*:* 6 (including)